PatchSiren

edgelesssys CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH edgelesssys CVE published 2026-09-27

CVE-2026-100839

CVE-2026-100839 is a high-severity vulnerability in Contrast, a confidential-computing runtime for Kubernetes. The issue allows for AML injection attacks, enabling an attacker to execute arbitrary code and access or modify confidential guest data. This vulnerability affects AMD SEV-SNP platforms Metal-QEMU-SNP and Metal-QEMU-SNP-GPU. Version 1.18.0 mitigates the attack by sandboxing the kernel AML interpreter.

HIGH edgelesssys CVE published 2026-09-27

CVE-2026-100838

CVE-2026-100838 is a high-severity vulnerability in Contrast, a confidential-computing runtime for Kubernetes. Versions before 1.19.1 contain a flaw in the CopyFile verification that allows arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critical files in the gue [truncated]

HIGH edgelesssys CVE published 2026-09-27

CVE-2025-71426

CVE-2025-71426 debrief: Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery. A recovering Coordinator does not verify the seed supplied by the recovering party, allowing an attacker to stand up a rogue Coordinator and impersonate a workload owner. This vulnerability affects Kubernetes deployments using Contrast before 1.4.1, allowing an attacker to impersonate a workload owner and [truncated]

HIGH edgelesssys CVE published 2026-09-27

CVE-2025-71425

CVE-2025-71425 debrief: Contrast before 1.8.1 Information Disclosure via Logging. The vulnerability allows unauthorized access to workload secrets via logging. Affected deployments should verify and upgrade to Contrast version 1.8.1 or later, review logging configurations, and restrict access to Kubernetes logs. This issue is particularly concerning as it exposes sensitive information to Kubernetes users [truncated]

MEDIUM edgelesssys CVE published 2026-09-27

CVE-2025-71424

CVE-2025-71424 debrief: Edgeless Systems Contrast before 1.9.1 insecure volume mount allows untrusted host to write arbitrary file trees inside confidential containers on bare-metal deployments. This issue arises from the VOLUME directive in a Dockerfile, which is not handled specially by Kubernetes but is used by containerd to add a mount point. On bare-metal Contrast deployments running an image with at [truncated]

HIGH edgelesssys CVE published 2026-09-27

CVE-2025-71423

A confidential-computing runtime for Kubernetes, Edgelesssys Contrast, exposed workload secrets in its initializer logs before version 1.12.2. This issue allows any Kubernetes user with get or list permission on pods/logs to access these secrets, potentially compromising encrypted storage and Vault integration. The vulnerability was introduced in version 1.9.0 and patched in version 1.12.2. Defenders shou [truncated]

MEDIUM edgelesssys CVE published 2026-09-27

CVE-2025-71422

Contrast, a Kubernetes runtime for confidential containers, has a vulnerability in its secure persistent volume feature. The vulnerability allows a malicious host to supply a crafted LUKS2 volume to a pod VM, potentially leading to exposure of confidential data. Defenders should prioritize verifying exposure of Contrast versions before 1.12.1, assessing inventory for potentially vulnerable deployments, an [truncated]